trustwave kayıtları
trustwave üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %61,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-255 Credentials Management Errors2
- CWE-476 NULL Pointer Dereference2
- CWE-170 Improper Null Termination1
- CWE-172 Encoding Error1
- CWE-306 Missing Authentication for Critical Function1
- CWE-436 Interpretation Conflict1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
43Planlayın | CVE-2017-18001Kavram kanıtı | Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorizetrustwave · secure web gateway · CWE-306 | Kritik9,8 | — | %13,8 | 31 Ara 2017 |
40Planlayın | CVE-2014-2727İstismar yok | The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.trustwave · mailmarshal · CWE-78 | Kritik9,8 | — | %1,9 | 19 Şub 2020 |
31İzleyin | CVE-2013-1915İstismar yok | ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of servitrustwave · modsecurity · CWE-611 | Yüksek7,5 | — | %4,2 | 25 Nis 2013 |
31İzleyin | CVE-2021-42717Kavram kanıtı | ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects.owasp · modsecurity · CWE-674 | Yüksek7,5 | — | %3,1 | 7 Ara 2021 |
31İzleyin | CVE-2025-27110İstismar yok | Libmodsecurity3 has possible bypass of encoded HTML entitiestrustwave · modsecurity · CWE-172 | Yüksek7,9 | — | %0,5 | 25 Şub 2025 |
30İzleyin | CVE-2022-48279İstismar yok | In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewowasp · modsecurity · CWE-436 | Yüksek7,5 | — | %1,2 | 20 Oca 2023 |
30İzleyin | CVE-2023-24021İstismar yok | Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer overtrustwave · modsecurity · CWE-170 | Yüksek7,5 | — | %0,9 | 20 Oca 2023 |
30İzleyin | CVE-2024-46292İstismar yok | A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name paratrustwave · modsecurity · CWE-120 | Yüksek7,5 | — | %0,8 | 9 Eki 2024 |
30İzleyin | CVE-2025-47947İstismar yok | ModSecurity Has Possible DoS Vulnerabilitytrustwave · modsecurity · CWE-1050 | Yüksek7,5 | — | %0,6 | 21 May 2025 |
24İzleyin | CVE-2009-1902Kavram kanıtı | The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapotrustwave · modsecurity · CWE-476 | Orta5,0 | — | %13,7 | 3 Haz 2009 |
24İzleyin | CVE-2013-2765Kavram kanıtı | The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereferencapache · http server · CWE-476 | Orta5,0 | — | %13,7 | 15 Tem 2013 |
24İzleyin | CVE-2012-4528Kavram kanıtı | The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data totrustwave · modsecurity | Orta5,0 | — | %12,5 | 28 Ara 2012 |
21İzleyin | CVE-2013-5705İstismar yok | apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalizetrustwave · modsecurity | Orta5,0 | — | %2,7 | 15 Nis 2014 |
20İzleyin | CVE-2011-1906İstismar yok | Trustwave WebDefend Enterprise before 5.0 7.01.903-1.4 stores specific user-account credentials in a MySQL database, which makes it easier ftrustwave · webdefend · CWE-255 | Orta5,0 | — | %1,1 | 5 May 2011 |
20İzleyin | CVE-2011-0756İstismar yok | The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote atttrustwave · webdefend · CWE-255 | Orta5,0 | — | %1,1 | 4 May 2011 |
18İzleyin | CVE-2012-2751İstismar yok | ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in thtrustwave · modsecurity | Orta4,3 | — | %3,3 | 22 Tem 2012 |
18İzleyin | CVE-2009-1903İstismar yok | The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a rtrustwave · modsecurity | Orta4,3 | — | %3,0 | 3 Haz 2009 |
18İzleyin | CVE-2009-5031İstismar yok | ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filteritrustwave · modsecurity · CWE-79 | Orta4,3 | — | %2,9 | 22 Tem 2012 |
- CVE-2017-1800143Planlayın
Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorize
KritikCVSS 9,8Kavram kanıtıEPSS %14trustwave · secure web gateway31 Ara 2017
- CVE-2014-272740Planlayın
The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.
KritikCVSS 9,8İstismar yokEPSS %2trustwave · mailmarshal19 Şub 2020
- CVE-2013-191531İzleyin
ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of servi
YüksekCVSS 7,5İstismar yokEPSS %4trustwave · modsecurity25 Nis 2013
- CVE-2021-4271731İzleyin
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects.
YüksekCVSS 7,5Kavram kanıtıEPSS %3owasp · modsecurity7 Ara 2021
- CVE-2025-2711031İzleyin
Libmodsecurity3 has possible bypass of encoded HTML entities
YüksekCVSS 7,9İstismar yokEPSS %0trustwave · modsecurity25 Şub 2025
- CVE-2022-4827930İzleyin
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firew
YüksekCVSS 7,5İstismar yokEPSS %1owasp · modsecurity20 Oca 2023
- CVE-2023-2402130İzleyin
Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over
YüksekCVSS 7,5İstismar yokEPSS %1trustwave · modsecurity20 Oca 2023
- CVE-2024-4629230İzleyin
A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name para
YüksekCVSS 7,5İstismar yokEPSS %1trustwave · modsecurity9 Eki 2024
- CVE-2025-4794730İzleyin
ModSecurity Has Possible DoS Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1trustwave · modsecurity21 May 2025
- CVE-2009-190224İzleyin
The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapo
OrtaCVSS 5,0Kavram kanıtıEPSS %14trustwave · modsecurity3 Haz 2009
- CVE-2013-276524İzleyin
The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereferenc
OrtaCVSS 5,0Kavram kanıtıEPSS %14apache · http server15 Tem 2013
- CVE-2012-452824İzleyin
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to
OrtaCVSS 5,0Kavram kanıtıEPSS %13trustwave · modsecurity28 Ara 2012
- CVE-2013-570521İzleyin
apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalize
OrtaCVSS 5,0İstismar yokEPSS %3trustwave · modsecurity15 Nis 2014
- CVE-2011-190620İzleyin
Trustwave WebDefend Enterprise before 5.0 7.01.903-1.4 stores specific user-account credentials in a MySQL database, which makes it easier f
OrtaCVSS 5,0İstismar yokEPSS %1trustwave · webdefend5 May 2011
- CVE-2011-075620İzleyin
The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote att
OrtaCVSS 5,0İstismar yokEPSS %1trustwave · webdefend4 May 2011
- CVE-2012-275118İzleyin
ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in th
OrtaCVSS 4,3İstismar yokEPSS %3trustwave · modsecurity22 Tem 2012
- CVE-2009-190318İzleyin
The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a r
OrtaCVSS 4,3İstismar yokEPSS %3trustwave · modsecurity3 Haz 2009
- CVE-2009-503118İzleyin
ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filteri
OrtaCVSS 4,3İstismar yokEPSS %3trustwave · modsecurity22 Tem 2012